> For the complete documentation index, see [llms.txt](https://summerain-1.gitbook.io/summerain/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://summerain-1.gitbook.io/summerain/zh-cn/she-qu/security.md).

# 安全策略

## 报告漏洞

如果你发现安全漏洞，**请勿公开提交 Issue**。

请通过 [GitHub Security Advisories](https://github.com/kserksi/summeRain/security/advisories/new) 私下报告。我们会尽快确认报告并评估其影响。

请尽量提供以下信息：

* 对问题及其影响的清晰描述
* 复现步骤，最好包含最小可复现示例
* 受影响的版本
* 建议的修复方案（如有）

## 响应流程

1. 我们会在 72 小时内确认收到报告。
2. 我们会评估严重程度并验证漏洞。
3. 我们会开发修复，并在严重程度需要时使用私有分支。
4. 我们会发布修复版本，并在报告者同意的情况下公开致谢。

## 支持的版本

仅从 `main` 发布的最新稳定版本接收安全修复。`dev` 分支的开发构建属于预览版本，不支持生产使用。旧版本不单独维护安全补丁。

## 部署安全

完整指南请参阅 [docs/USAGE.md](/summerain/zh-cn/yong-hu-yu-yun-wei/usage.md)。关键要求包括：

* 生产环境必须为 `COOKIE_SECRET`、`IMGPROXY_KEY` 和 `IMGPROXY_SALT` 设置强随机值。
* 带 `__Host-` 前缀的 Cookie 要求 HTTPS 和同源部署。本地开发必须使用自签名证书。
* MySQL、Redis 和 imgproxy 容器应仅位于私有网络，不得公开暴露端口。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://summerain-1.gitbook.io/summerain/zh-cn/she-qu/security.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
